# Centrifugo (slim) > Centrifugo is an open-source, self-hosted realtime messaging server from Centrifugal Labs. A backend publishes to channels through its HTTP or gRPC server API, and subscribers receive messages over WebSocket, SSE, HTTP streaming or gRPC. - Full: https://www.anchorterminal.com/tools/centrifugo.md (~6,500 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/centrifugo.json · canonical https://www.anchorterminal.com/tools/centrifugo - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 63.1/100 · rank #407 of 950 · #8 in Event delivery & webhooks · not agent-ready · confidence medium** Assessment: Centrifugo is Apache-2.0 software an owner runs, with a 40-operation Swagger file, idempotency keys on publish and seven releases in the 90 days to 28 September 2026. The server API has one all-powerful key, which the docs also accept in the URL, and eleven security advisories were published between February and September 2026, two rated Critical. ## Facts - Kind: HTTP API · vendor: Centrifugal Labs LTD · category: Event delivery & webhooks · legal entity: Centrifugal Labs LTD · provenance 41/100 - Local only (HTTP): oci `centrifugo/centrifugo` - Auth: API key · pricing: Free · x402: no · licence: Apache-2.0 for the open-source server. Centrifugo PRO is a closed commercial build under the Centrifugo PRO Licence Agreement - Probe metrics: not measured yet (probes haven't run) - Surface graded: The open-source server an owner runs, through its HTTP server API (default `http://localhost:8000/api`) and gRPC server API. No hosted service and no MCP server found - API: POST with a JSON body per method. publish, broadcast, subscribe, unsubscribe, disconnect, refresh, presence, presence_stats, history, history_remove, channels, info, batch, plus map and shared poll methods. The Swagger file has 40 operations, PRO methods among them - Credentials: One key in `http_api.key`, sent as `X-API-Key` or, as a documented option, `?api_key=`. `grpc_api.key` for gRPC. Clients connect with JWTs or through a connect proxy. JWKS authentication for the server API is PRO only - Delivery: At most once by default. Channel history with recovery or positioning gives at least once within retention. Engines are Memory, Redis and NATS (NATS without history) - Idempotency: `idempotency_key` on publish and broadcast, per channel, results cached for five minutes, Memory and Redis engines only. `version` and `version_epoch` drop stale document updates - Errors: Codes 100, 102, 104, 107, 108, 111, 112 and 113 with a message, and a `temporary` flag in the Swagger file. 200 with an `error` object by default, HTTP or gRPC codes in `transport` error mode - Rate limits: None on the server API in the open-source edition. Operation rate limits per connection and per user are in PRO only. PRO sandbox mode allows 5 API requests a second - Async input: Consumers read API commands from Kafka, Redis Streams, a PostgreSQL outbox table, NATS JetStream, Google Pub/Sub, AWS SQS and Azure Service Bus - Client transports: WebSocket, HTTP streaming, SSE, WebTransport (experimental) and gRPC, with unidirectional variants that need no SDK - Libraries: Official HTTP API libraries cent (Python), phpcent (PHP), gocent (Go) and rubycent (Ruby). Official client SDKs for JavaScript, Go, Dart, Swift, Java and Python, with C# in progress - Install: Single static binary for Linux (amd64, arm64, armv6), macOS (amd64, arm64), Windows and FreeBSD. Docker image `centrifugo/centrifugo`, deb and rpm on packagecloud, Helm chart, Homebrew tap - Admin: Web UI off by default, behind `admin.password` and `admin.secret`. Swagger UI at `/swagger` when `swagger.enabled` is set, on the internal port - Telemetry: Anonymous usage counters sent once in 24 hours, on by default. `usage_stats.disabled` turns them off - Licence: Apache-2.0 for the server. Centrifugo PRO is closed, under the Centrifugo PRO Licence Agreement at https://centrifugal.dev/license - Releases: v6.9.7 on 28 September 2026, built with Go 1.26.8. Notes are on the GitHub releases page, and `CHANGELOG.md` stops at v5.1.1 - Prices: Centrifugo open-source server (self-hosted) free per month (plan) - Scores: Reliability 86, Performance pending, Schema & documentation 81, Agent ergonomics 76, Security & auth 37, Payments & pricing 60, Task success pending, Maintenance & community 86, Transparency & trust 56 · negative events -6 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because Centrifugo is a server the owner runs and has no hosted service. · Schema & documentation, A Swagger 2.0 file with 40 operations and 162 definitions and an `api.proto` are in the repository, and the server can show the file at… · Agent ergonomics, `history` returns only the stream position unless `limit` is set, and `channels` takes a glob `pattern`. · Security & auth, The server API has one key for every method, set in the configuration file and changed by editing it. · Payments & pricing, Read with the self-hosted rule, on the open-source server an agent would use. · Maintenance & community, v6.9.7 was tagged on 28 September 2026, 11 days before this check (30). · Transparency & trust, The server is open source under Apache-2.0. Centrifugo PRO is a separate closed build (30). - Sources: 15, open questions: 8, both in the full twin - Capabilities: events.realtime - JSON: https://www.anchorterminal.com/api/v1/tools/centrifugo.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/centrifugo.svg` or a link to https://www.anchorterminal.com/tools/centrifugo from a page on centrifugal.dev or one of its subdomains, or the README of github.com/centrifugal/centrifugo, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Check every response for an `error` field, or send `X-Centrifugo-Error-Mode: transport` to get HTTP status codes. Batch and broadcast replies still need per-item checks 2. Send `idempotency_key` on publish and broadcast before retrying. It works per channel for five minutes, on the Memory and Redis engines only 3. Call `history` with `limit`. Without it the result holds only `offset` and `epoch`, and history is off until the namespace enables it 4. Send the key in the `X-API-Key` header, never as `?api_key=`. For gRPC set metadata `authorization` to `apikey ` 5. Avoid `channels` on a large deployment. It returns every active channel with no pagination, so pass `pattern` ## Connect ```bash curl -sSLf https://centrifugal.dev/install.sh | sh ``` ```bash curl --header "X-API-Key: " \ --request POST \ --data '{"channel": "test", "data": {"value": "test_value"}}' \ http://localhost:8000/api/publish ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/centrifugo ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Ably | BB | 75 | events.realtime | https://www.anchorterminal.com/tools/ably.min.md | | PubNub | B | 68.1 | events.realtime | https://www.anchorterminal.com/tools/pubnub.min.md | | Pusher Channels | D | 51.9 | events.realtime | https://www.anchorterminal.com/tools/pusher-channels.min.md | | Hookdeck | BB | 76.9 | same category | https://www.anchorterminal.com/tools/hookdeck.min.md | | Svix | BB | 74 | same category | https://www.anchorterminal.com/tools/svix.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)